Try our new research platform with insights from 80,000+ expert users
Senior Engineering Manager at Happiest Minds Technologies
Real User
Provides integrations, enables customizations, and has a good security posture and a helpful support team
Pros and Cons
  • "The product has a good security posture."
  • "The glass table feature does not perform as expected."

What is our primary use case?

We have many use cases for firewall logs in our system. We collect logs from these firewalls and customize our use cases.

What is most valuable?

The triad is one of the best features. The product has a good security posture. It provides many customizations.

What needs improvement?

The glass table feature does not perform as expected. It must be improved.

For how long have I used the solution?

I have been using the solution for seven years.

Buyer's Guide
Splunk Enterprise Security
August 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,497 professionals have used our research since 2012.

What do I think about the stability of the solution?

The tool is stable. I rate the stability a seven or eight out of ten.

What do I think about the scalability of the solution?

I rate the product's scalability an eight out of ten.

How are customer service and support?

If something doesn't work, we reach out to the support team. The support provided by the team is great. The support is part of the entitlements in the license we buy.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I'm using Microsoft Sentinel. It is a cloud-native tool. Compared to Splunk Enterprise Security, Microsoft Sentinel is easier to handle. We use Splunk Enterprise Security because we have to manage a big infrastructure and may have many security vulnerabilities. The cybersecurity team decided to use Splunk Enterprise Security. The volume of data is high, so it is easier to manage it in Splunk.

How was the initial setup?

The initial deployment was complex. If we need to customize the solution, we need one to four weeks to get all the data, manage the license, and calculate the resources.

What's my experience with pricing, setup cost, and licensing?

The solution is costly. The cost is calculated based on the volume of data ingested per day.

What other advice do I have?

It is not complicated to monitor multiple cloud environments using Splunk. It is one of the best solutions. The multiple cloud integration is open source. It's really helpful to monitor the structure and user authentication. I would definitely suggest it to people.

It's feasible to achieve visibility into multiple environments using the product. The cloud solution is recommendable. The on-premise product is tedious to manage, but it will be easier if we have a good resource to take care of the administration as an architect.

The tool has threat-detection capabilities. There are some limitations. We have a set of rules and patterns where we collect the tagging and the data we want to alert. It would have been better if detection and threat analysis recommendations were available out of the box. Though the solution keeps updating with the market demands, I still feel that the feature needs to be more reactive.

The product has inbuilt use cases for analyzing malicious activities and detecting breaches. It helps us run our alerts to catch malicious actions like brute force attacks or user-related authentication challenges. Splunk Enterprise Security has helped us reduce our alert volume. It has many automations and integrations. The SOAR tool detects and automatically manages repetitive and generic alerts proactively.

Splunk Enterprise Security helps us speed up our security investigations. It's at the top of its game. The tool is proactive and helps us take action before something happens. It has reduced our security threats. It is saving us hours of investigation. If you have a big data source, then I would recommend Splunk Enterprise Security. It will be easy for you to manage the data load. If you do not have a high data volume, you can look for other solutions like Sumo Logic.

My experience with the solution is really good. It has the capability to analyze the platform and take care of vulnerabilities. There is scope for improvement. We have a huge data volume of 2 TB per day. Our platform needs a solution like Splunk Enterprise Security to maintain the data volume and filter out our security vulnerability logs.

Overall, I rate the product a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior Security Engineer at a comms service provider with 1,001-5,000 employees
Real User
Top 20
Helpful for detecting anomalies and malicious activities and reducing false alerts
Pros and Cons
    • "The integration feature with other applications, such as anti-DDoS application Arbor, needs to be more powerful."

    What is our primary use case?

    We use Splunk Enterprise Security to detect different anomalies and alerts based on our infrastructure. I work in the telecom industry. We have multiple network and security devices that collect logs. We create use cases to collect logs from all these devices.

    What is most valuable?

    The dashboards are very good in Splunk Enterprise Security. There are pretty good options to fine-tune the alerts, to wipe out false positives, and only get the correct alerts as per our requirements. The UI is pretty good and easy to use because it is integrated with different EDR tools. This integration is very helpful for identifying different malicious activities or malware for any of the endpoints, especially the critical servers.

    The architecture of Splunk Enterprise Security is really good at collecting and parsing logs. Each detail, how it correlates, and all the features are up to the mark compared to other vendors. The indexing speed is pretty good in Splunk Enterprise Security. 

    I used many of its machine learning automatic detections. It's really helpful to identify any malicious activity or the behavior of malware over time. There was a malicious activity that involved privilege escalation from the MITRE ATT&CK framework. It was very helpful in detecting that escalation, and due to Splunk Enterprise Security's machine learning capability, we tracked down the malware, remediated it, and prevented it from spreading further to other endpoints.

    What needs improvement?

    There should be more options for adding more visual experience in terms of dashboards. 

    The integration feature with other applications, such as anti-DDoS application Arbor, needs to be more powerful.

    For how long have I used the solution?

    I have been using it for almost three years.

    What do I think about the stability of the solution?

    Issues are very rare, near to zero with no downtime. 

    What do I think about the scalability of the solution?

    It is highly scalable.

    How are customer service and support?

    The tech support is really good. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I use ArcSight as well. We did not fully migrate to Splunk Enterprise Security. We are using both solutions.

    Splunk Enterprise Security has good refresh rates for getting alerts. I prefer Splunk Enterprise Security more compared to other competitors such as ArcSight or IBM QRadar. The health checks are very good. The dashboards, indexing speed, correlations, and machine learning are advantages of Splunk Enterprise Security. Even though other competitors offer the same features, the efficiency of Splunk Enterprise Security is the best.  Except for the price, I don't find any disadvantages compared to other vendors.

    How was the initial setup?

    The migration process was complex because we were moving from one SIEM tool to another. In the telecommunications industry, there are several teams that we needed to collaborate with, and meetings were essential. Within the network team alone, there are numerous sub-teams to coordinate with.

    In my current environment, this complexity made the process challenging. We weren't starting from scratch; instead, we were transitioning from an existing SIM tool to a new one. If we had been implementing the first SIM tool for our company, it would have been much easier. However, migrating from one SIM to another always presents difficulties.

    What about the implementation team?

    Our company purchased through resellers.

    What's my experience with pricing, setup cost, and licensing?

    It's somewhat pricey compared to other vendors. However, for big infrastructure companies such as telecom, the price is fair enough. Compared to the features and efficiency it offers, the price is good. For medium-sized companies, it's too pricey.

    What other advice do I have?

    I would rate Splunk Enterprise Security an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Splunk Enterprise Security
    August 2025
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
    867,497 professionals have used our research since 2012.
    reviewer2512353 - PeerSpot reviewer
    Director, Information Technology at a government with 501-1,000 employees
    Real User
    Top 20
    Offers complete visibility into the environment, centralize management but latency issues when using cloud services

    What is our primary use case?

    We have an engineering team working on the back end to receive data, they do data modeling, and create dashboards. That's been pretty useful.

    How has it helped my organization?

    Splunk Enterprise Security helped our organization a lot. In the past, we relied on every single product that had its own kind of audit trail information. We needed to go and look for it, for example, in the Windows environment. We have to use the event viewer a lot to look for certain things, like system applications and security logs. In Linux, we have to use the log file, and under certain applications in the Linux environment, we have to look at the logs for that as well.

    That's just part of the operating system. It is not the infrastructure, like network devices. When we centralize logs, we put everything in one location. 

    Our advanced users can do the SPL query anything they want. Executives or higher-up management users need to look for certain things, like how many systems are missing patches for this month or who logged in today from where, what they did, and how often they re-authenticated to the systems. 

    We have a lot of data from businesses, data from our devices, and more. When we put it all in the ES, it gives us the ability to look at certain functions. It provides more insight into our data, where it's traveling from, between endpoints, and what they're doing with it. 

    We also look into performance. We use other monitoring tools as well, and that data is also piped into Splunk. We have a centralized platform that we can navigate to look for everything we need rather than having to go to each individual system, like Cisco Syslog or we have to go to the Forcepoint console to look for it. It is a centralized platform that gives us more insights into our data or what's happening in general. 

    It is very important that Splunk Enterprise Security provides end-to-end visibility into our environment because, at any given point in time, we want to know what's happening to the data. Data privacy is the primary concern. We want to make sure that authorized users get access to what they are authorized to so that data would not leak out or travel from a different path. Again, we get a lot of data in there. We understand more about our data to improve the business in certain aspects.

    We know that during certain times of the day, a lot of people access a server or website.

    Then it'll give us more insight about where we need more network bandwidth or where we need to upgrade network devices. We understand more about our data, like how many people access the data lake house. And that's just for performance. 

    On the security side, we would know who's accessing it from where. Are they authorized to do so, or is there any weird access pattern in locations that they're not supposed to be in?

    So again, we get the data, we centralize it, and we can do data mining. We can pull out anything from there rather than looking all over the place, like, "I want to find out if he's working today if someone's using his account, or from which devices he accessed data from two different places."

    From Splunk Enterprise, we can either do it manually or have our engineers create an audit dashboard. Or, if you are an advanced user, you can do SPL queries that will give you anything you need.

    The alert volume depends on the users. If they do what they're supposed to, then there's nothing to talk about. If not, it's more or less on how you manage the data, educate your users, and control your system. Based on that, Splunk might play zero, fifty percent, or seventy-five percent role.

    In a way, it has helped improve our organization's business resilience. It's a way for us to predict the pattern of data access and other things going on.

    Knowing a way to do that, if we have enough resources to do it, is fine because we have so much data, but no one's really monitoring it. If we get alerts in the middle of the night and we don't have anyone to handle it, it's not going to help.

    It's another aspect that we worry the most about, where our data is floating. 

    Now that we've centralized our log information into Splunk, we want it to be secured well because now users can predict a pattern of data access from where, and from whom. 

    What is most valuable?

    We put all of our logs and data into Splunk, like network switches, firewalls, and web-based protection. In general, every component within the infrastructure sends data to Splunk. 

    Then, we have an engineering team transforming, manipulating, and analyzing the data to create a front-end dashboard in a meaningful way.   

    What needs improvement?

    With the new announcement of version eight, it's going to give us a single point-and-click. On the front page there, that will give us a whole lot of information that we need to look into on the right panel without navigating down or going to more details, clicking here and there.

    For how long have I used the solution?

    We've been using it for quite a few years now.

    Which solution did I use previously and why did I switch?

    The solution of choice depends on the engineers and teams. If they manage Linux, they're comfortable with certain tools to read the logs. In a Windows environment, it depends on the engineers. They favor any certain tool; they would do it, but it would be to cut down costs and consolidate all the software strings.  

    Splunk was not that big years ago. But then we started seeing that they put more investment into it and made the tool more useful.

    How was the initial setup?

    We're not using the cloud version yet. This is just the enterprise product on-premises.

    What's my experience with pricing, setup cost, and licensing?

    Splunk can improve the pricing. People like certain features, and sales use the features that they provide, the automated features, to hook customers into paying for the big-price license.

    Everyone does it, like Microsoft and Cisco. Initially, you try out the free version, but once you get it in your shop and turn it into production, you start relying on it and don't want to get out. You start paying a lot more for it.

    What other advice do I have?

    Splunk is on the right path. It's good, but it does not provide everything that we need. There's a lot more to it. I look at it as ideal for detecting in real-time, but we're always behind and just look at the log information. 

    If you have a network device, a Splunk Enterprise instance, and you have to send data to it. You're relying on network connections. 

    If you're using a cloud service or anything where Splunk is not on-premises, there's high latency. If that network connection is down, that's it. You don't know what's going on. So even if you have it on-prem, you're still relying on it after the fact. 

    When you look at Splunk, you're looking at things that have already happened. It's nothing that's actively going out there and doing something for you. 

    If you had to give it a number, from one to ten, since they've gone this far, I'd give it a five or six. Because locking or monitoring is just a part of business, and how you're going to receive those alerts and act on them is another part of it, when I look at the overall infrastructure and infrastructure management.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2499612 - PeerSpot reviewer
    Senior Security Engineer at a financial services firm with 5,001-10,000 employees
    Real User
    Helps us fully understand the origin of threats and where we need to go next to go in our investigative process but lacks SOAR and AI integrations
    Pros and Cons
    • "The most valuable feature is the ability to look at threats and link them to the MITRE ATT&CK framework."
    • "We don't have SOAR products from Splunk. I believe that's an important piece."

    What is our primary use case?

    I work on the engineering side, so we build for the SOC. The use cases revolve around how the SOC can better leverage the toolset and how we can improve the tool for the SOC to better identify threats within the environment.

    How has it helped my organization?

    I have used it in previous jobs and found it very useful there. It's important for our organization to have end-to-end visibility. 

    We don't have SOAR products from Splunk. I believe that's an important piece if it is offered with this platform to fully have the enterprise end-to-end visibility. While Splunk's offering is great, and we should consider leveraging it, we do have another platform in place. We need to carefully evaluate how Splunk's offerings integrate into the environment to provide that end-to-end visibility.

    From the threat landscape view within Splunk Enterprise Security, it is valuable. The fields that are available provide a high-level overview of what is in front of us and drill down further to see the threat landscape that is in your environment. You can further investigate these threats in the Attack Analyzer. So, even with our current setup, we can achieve a degree of end-to-end visibility and threat analysis within the platform.

    Splunk Enterprise Security helped improve our organization's ability to ingest and normalize data.

    Before this, we used a different SIEM solution, but there was no visualization to it. Splunk gives us the ability to correlate data from different sources, see it in real-time, pull it all together from different landscapes of data sources, pull it all together, and look at the timelines of events about what's going on. It helps to narrow down quickly.

    The recent feature updates with AI integrations are even more promising. I believe these will further enhance the SOC's ability to quickly identify threats and, hopefully, mitigate them before they propagate throughout our environment.

    What is most valuable?

    The most valuable feature is the ability to look at threats and link them to the MITRE ATT&CK framework. This helps our staff identify threats within our environment and appropriately landscape them.

    Splunk Enterprise Security provides us with relevant context to help guide our investigations. 

    At a high level, we can see threat details and then drill down further. It maps to important frameworks, like MITRE ATT&CK, to help us fully understand the origin of threats and where we need to go next to go in our investigative process.

    It integrates with other platforms like Attack Analyzer and SOAR, and soon, AI integrations. These will further help us reduce the threat landscape.

    What needs improvement?

    We don't have SOAR and AI integrations yet. 

    For how long have I used the solution?

    I've been using Splunk Enterprise Security for about a year, but we recently just onboarded Splunk to the organization, so we're still working on permissions that we used at a previous job. 

    We're still working on permissions within the organization.

    What do I think about the stability of the solution?

    It's a stable product. I've used other SIEMs. It is much easier to navigate. It is more user-friendly. It is understanding SPL (Search Processing Language), coming in, not knowing it at all. 

    It is much easier to go to the Splunk documentation, read the Splunk documentation, and understand, "Okay, this is what I'm looking for!" 

    At my previous company, they rolled out Splunk and said, "Okay, we're ingesting all the logs in Splunk. Now go and just do it." 

    There was no training involved, so I had to go and learn it on my own. And because while the logs were in the environment, I had to just go and go get the logs out of Splunk; I couldn't go to a server anymore or get logs the old-fashioned way. 

    I had to learn Splunk quite quickly. It was easy to navigate the documentation, read the documentation, go to the community site, and navigate the community site; getting that information was quite easy. 

    So it was a good experience, a much better experience in dealing with some other vendors. I've dealt with things like QRadar, and I had a difficult time even figuring out what their query language was and understanding how to translate that into actually getting a search to pull back data.  

    What do I think about the scalability of the solution?

    I've worked in some environments where it's been used extensively with enormous amounts of data. 

    In my current environment, we're still figuring out how much data to ingest and how it will be managed. We can adjust whatever we want, but it is an enormous amount of it because we are a "Big Data World" now. 

    I have used it in environments where we had data lakes upon data lakes. Scalability from Splunk's point of view wasn't an issue. It was able to scale quite easily. 

    The issue lies more on the business side like:

    • How to maintain that growth? 
    • How do you account for that growth? 

    I don't think the issue is really from the Splunk standpoint. It's on the business side: How do you make sure you account for that growth in your models?

    How are customer service and support?

    I had a good experience with support.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    Based on my limited experience, I'd rate it a seven out of ten. However, I have high expectations due to the integrations I see possible, such as SOAR and the upcoming AI integrations. The roadmap for it is out of this world. 

    I'm excited to see what Splunk has to offer with the Cisco offerings and the interconnectivity with Cisco.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2499738 - PeerSpot reviewer
    Cybersecurity Specialist at a manufacturing company with 10,001+ employees
    Real User
    Top 20
    Identifies threats with the help of features like correlation searches
    Pros and Cons
    • "Scalability-wise, the tool is awesome since you can add or reduce your resources in an easy way."
    • "Resource usage can probably be described as an area with shortcomings in the product where improvements are required."

    What is our primary use case?

    I have used the solution in my company since I was an admin for Splunk. Most of the people involved in the use cases associated with the product are those in the SOC team.

    How has it helped my organization?

    The tool has helped us to identify and analyze the possible threats. The product helps identify threats and do further investigations.

    In terms of the benefits I have seen from using Splunk Enterprise Security, I would say that we are still working on implementing Splunk tools.

    What is most valuable?

    The most valuable feature of the solution is correlation searches, which allow you to easily find threats and other such areas.

    It is really important that Splunk Enterprise Security provides end-to-end visibility into our company's environment, as it can help save time and make the response faster.

    Splunk Enterprise Security has helped improve our organization's ability to ingest and normalize data with the use of data models and Splunk CIM.

    The tool has helped reduce our company's alert volume as the identification process is fast.

    Splunk Enterprise Security provides our company with relevant context to help guide our investigations. Any incident can be resolved in a minimal amount of time than expected, and we can get more information about such incidents. It can be resolved mostly on the same day and even in a few hours.

    Splunk Enterprise Security helped reduce mean-time resolve. It has also helped improve our organization's business resilience. Considering the tool's ability to predict, identify, and solve problems in real-time, I would say that it keeps our company safe.

    Splunk's unified platform helps consolidate networking, security, and IT observability tools. I cannot provide too many details because I am not working directly on the analytics part.

    What needs improvement?

    I think in the near future, we want to have Splunk Enterprise Security complemented with Splunk SOAR because we have been checking the administrations. It is pretty cool, considering the things that you can do with Splunk Enterprise Security and Splunk SOAR together.

    Resource usage can probably be described as an area with shortcomings in the product where improvements are required.

    Our company just saw the latest version of the tool here in the Gulf. I am not sure, though, about it because what Splunk showed us was really impressive.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for five years. My company is a customer.

    What do I think about the stability of the solution?

    It is a stable solution. At my company, there are two Splunk admins. Splunk is so stable that though there are two Splunk admins in the company, nobody complains that something is not working. Stability-wise, I rate the solution a nine out of ten.

    What do I think about the scalability of the solution?

    Scalability-wise, the tool is awesome since you can add or reduce your resources in an easy way.

    How are customer service and support?

    The solution's technical support offered to users could be much more. At times, I get answers related to Splunk from the support team, which I feel are available on Google. I rate the technical support a seven or eight out of ten. I feel that sometimes the tool's support team uses Google to provide me with answers.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    It was harder to get it working and configured correctly in the past. Things have changed a lot since the first version of the tool was released. I honestly feel comfortable anytime the tool releases something new to be deployed or if there is a new upgrade.

    The solution is deployed on an on-premises model. I use the cloud services offered by Azure and AWS.

    What was our ROI?

    I have not seen a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    Splunk Enterprise Security is not a cheap product, but I think it is worth every dollar that you pay.

    What other advice do I have?

    Considering that the initial configuration is difficult, I rate the solution an eight out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1880670 - PeerSpot reviewer
    Senior Director, Detection Engineering Cyber Defense Services at a insurance company with 5,001-10,000 employees
    Real User
    Top 20
    Offers users with a single-point-of-view dashboard for incident response
    Pros and Cons
    • "It is a very stable solution. I never really had a hiccup with the tool."
    • "The area of concern revolves around the fact that Splunk is an expensive product."

    What is our primary use case?

    I use the solution in my company, and most of the use cases are security-specific. My company uses it to transfer from our detection engineering team to our incident response team. For observability, our company is looking for security events within the tool, and we are logging all the critical security infrastructure and security-relevant logs to a platform for security operations.

    How has it helped my organization?

    The tool has helped to streamline our company's mean time spent in understanding security-relevant events and mitigating those risks.

    What is most valuable?

    Some of the tool's best features are RBA and UBA. I also like the tool's single point-of-view dashboard for incident response. The case management area is one of its good features.

    The tool has reduced the mean time needed to resolve. The reason is that the dashboard offers a single point of view, especially in areas where people aren't spread out. Our company is getting all the relevant data in there, and we are able to identify the problem instead of having to go to multiple tools or different interfaces.

    It is very important for our organization that Splunk Enterprise Security provides end-to-end visibility into our environment. It is our company's way of understanding what is going on in our environment, and then it is our way of handling security events, relevant events, mitigating risk, understanding risk, quantifying risk, producing metrics, and everything else.

    Splunk Enterprise Security provides our company with the relevant context to help guide our investigations. The tool has allowed us to gain better visibility and accuracy into security events.

    The tool has helped our company improve the resiliency of our security operations. This is based on the fact that we don't have full adoption of the tool for all users in our organization, especially not Splunk Enterprise Security.

    My company uses the tool for security operations, and we have built our security operations around Splunk based on what it can do and its performance.

    What needs improvement?

    I think Splunk is already improving its products. Some of the features that Splunk has been bringing out, like Splunk Attack Analyzer, while covering some of the other areas, like regulatory compliance and asset security, are good. It is just a matter of the customers being able to see the new features introduced by Splunk and get a demo to see if it makes sense for their work.

    I already have Splunk Enterprise Security set up. My company is interested in seeing Splunk Attack Analyzer, and that is why we are dealing with Splunk's point of contact right now.

    The area of concern revolves around the fact that Splunk is an expensive product. Splunk's expensive nature is an aspect where improvements are needed.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for six to seven years.

    What do I think about the stability of the solution?

    It is a very stable solution. I never really had a hiccup with the tool. Even for migrations or anything, our company has never had to use Splunk's partners, and it has been a seamless process.

    What do I think about the scalability of the solution?

    The tool's scalability has been good, but it depends on the organization and how Splunk is being adopted there.

    How are customer service and support?

    The solution's technical support can be hit or miss, but it is mostly positive. I can't give you all the scenarios, but the one thing that I do like about Splunk is that if there ever is a hiccup, a simple phone call from our end can ensure that Splunk's technical team takes care of our problems. I rate the technical support a ten out of ten.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    I have used many products in the past, but they were not in my present organization. It has been a long time since I used some products, as it was done back during my engineering days. I used to use HPE ArcSight. I have been through McAfee products, such as McAfee Nitro, back in the day. I have been an active Splunk business owner for almost a decade now.

    How was the initial setup?

    The product's initial setup phase has been perfect since our company uses the cloud services offered by Splunk.

    The solution is deployed on the cloud services offered by Splunk.

    What about the implementation team?

    The reseller that my company gets in touch with to help with the implementation part is called GuidePoint Security. My company's experience with GuidePoint Security has been good.

    What was our ROI?

    I think that based on my experience in the organizations that I have been in with Splunk, the tool definitely fetches a return on investment because it allows us to streamline security-relevant events that we need to take care of quickly. Overall, the tool saves us from any impact on our finances and business.

    What's my experience with pricing, setup cost, and licensing?

    Most of Splunk's customers are trying to find ways to keep the pricing from the ingest licensing model of Splunk down. What that comes down to is that we have to manage the platform. For our company, being a security enterprise and using it for security-relevant data allows us to streamline and control the ingest licensing model because we don't put in a lot of stuff in the tool. We have other things that we output to different data lakes. Splunk has always been on the expensive side.

    What other advice do I have?

    The ease of deploying the tool, its great customer service, and the development you can do within the tool is very seamless, so I would recommend the product to my peers since it is a great solution.

    I rate Splunk Enterprise Security a ten out of ten.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Focused ops analyst at Navy Federal Credit Union
    Real User
    Top 20
    Has the best search capabilities by far
    Pros and Cons
    • "I very much enjoy Splunk's robust search nature, which enables me to find the data I want within the data I have."
    • "There's been a big push for SBC compute over the ingestion model, which will hamper us."

    What is our primary use case?

    We use the solution for monitoring and detection and for threat hunting.

    How has it helped my organization?

    On the threat-hunting side, we can easily hunt down what we're looking for because Splunk's language parses the data coming in and allows us to utilize it to filter down through the data we need.

    What is most valuable?

    I very much enjoy Splunk's robust search nature, which enables me to find the data I want within the data I have. It's helpful for doing an investigation, whether that's an incident response or threat hunting.

    It is important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment. That way, we can see where the data is throughout the entire process, depending on where we are in the incident.

    Splunk Enterprise Security has helped improve our organization’s ability to ingest and normalize data.

    Splunk Enterprise Security has, by far, the best search capabilities. It ties that into alerts and notables, allowing you to refine what you want to see in your data.

    What needs improvement?

    There's been a big push for SBC compute over the ingestion model, which will hamper us. We're trying to increase our search counts with things like risk-based alerting, and I think that change will hinder our process.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for eight years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is a stable solution.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security is a scalable solution.

    What's my experience with pricing, setup cost, and licensing?

    I think we recently switched to the SVC pricing compared to the ingest pricing. I don't know if that was the right move for us.

    What other advice do I have?

    Overall, I rate the solution an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Kutay KOCA - PeerSpot reviewer
    Cyber Security Analyst at Clarusway
    Real User
    Top 10
    Is user-friendly, can easily monitor multiple environments, and reduces alerts
    Pros and Cons
    • "The most valuable feature of Splunk Enterprise Security is website activity monitoring."
    • "While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive."

    What is our primary use case?

    We use Splunk Enterprise Security to monitor our network environment for abnormal activities and threats.

    How has it helped my organization?

    We easily monitor multiple cloud environments with Splunk Enterprise Security.

    Insider threat detection helps our security posture.

    I use the threat intelligence management feature whenever I do a threat analysis.

    When Splunk detects breaches and malicious activities it notifies our IT team so they can analyze the notifications and respond accordingly.

    Splunk has helped our organization by allowing us to gain valuable insight through the analysis of large datasets.

    The customizable dashboards are user-friendly and visually appealing.

    It has helped reduce our alert volume.

    It has helped speed up our security investigations.

    What is most valuable?

    The most valuable feature of Splunk Enterprise Security is website activity monitoring.

    What needs improvement?

    While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for around five months.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    How are customer service and support?

    We frequently connect with the support team to review our options. They resolve our issues quickly.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We also use IBM QRadar but Splunk Enterprise Security is more functional and user-friendly.

    What's my experience with pricing, setup cost, and licensing?

    Splunk Enterprise Security is expensive.

    What other advice do I have?

    I would rate Splunk Enterprise Security eight out of ten.

    For someone who wants to use the cheapest solution, I would tell them that this is the best solution and worth the cost.

    I recommend Splunk Enterprise Security to others.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2025
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.